ESHYFT Data Breach Details
The breach was discovered by cybersecurity researcher Jeremiah Fowler, who reported the unsecured database on January 4, 2025. Fowler notified ESHYFT of the security lapse on January 6, 2025. Despite this notification, the database remained publicly accessible for over a month, until it was secured on March 5, 2025. The exact duration of the exposure prior to its discovery and whether unauthorized parties accessed the data during this period remain unknown.
The unprotected database, totaling 108.8 GB, contained 86,341 records, including, personal identification information,professional credentials, employment records, and medical documents. Additionally, a spreadsheet with over 800,000 entries detailed nurses’ internal IDs, facility names, shift times and dates, and hours worked.
What Information Was Compromised?
The compromised data may include:
-
Personal Identification Information: Scans of driver’s licenses and Social Security cards.
-
Professional Credentials: Professional certificates, resumes, and CVs.
-
Employment Records: Monthly work schedule logs and work assignment agreements.
-
Medical Documents: Records potentially containing diagnoses, prescriptions, or treatments, which may fall under HIPAA regulations.